CVE-2025-11363: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-11363 is an unauthenticated media file upload vulnerability in the Royal Addons for Elementor (Royal Elementor Addons and Templates) WordPress plugin. The flaw affects all versions before 1.7.1037 and stems from missing authorization checks on the wpr_addons_upload_file AJAX action, allowing any unauthenticated user to upload files to the server. It was discovered by researcher Envel Le Clainche, publicly disclosed on November 24, 2025, and assigned a CVE on December 15, 2025. The CVSS v3.1 base score is 5.3 (Medium), assessed by CISA-ADP (WPScan, Red Hat CVE).

Technical details

The root cause is improper authorization (CWE-434: Unrestricted Upload of File with Dangerous Type) on the wpr_addons_upload_file WordPress AJAX action handler. An unauthenticated attacker can obtain a nonce value exposed via the WprConfig JavaScript object (accessible after a Template Kit import) and use it to POST arbitrary files to wp-admin/admin-ajax.php. Uploaded files are stored in /wp-content/uploads/wpr-addons/forms, a publicly accessible directory. The PoC published by WPScan demonstrates exploitation using a simple curl command with a crafted multipart form request (WPScan).

Impact

Successful exploitation allows unauthenticated attackers to upload arbitrary media files to a publicly accessible directory on the WordPress server. While the CVSS score reflects a low integrity impact with no direct confidentiality or availability impact, the ability to upload files to a web-accessible path could be chained with other vulnerabilities (e.g., insufficient file type validation) to achieve remote code execution, web shell deployment, or serve malicious content to site visitors. The scope is limited to WordPress sites running the affected plugin versions (WPScan, Red Hat CVE).

Exploitability

A public proof-of-concept is available via WPScan, demonstrating exploitation with a single curl command requiring only a nonce obtainable from the frontend JavaScript object WprConfig. The EPSS score is 0.023% (very low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution or confirmed in-the-wild exploitation has been reported as of the available data (WPScan, Red Hat CVE).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Royal Elementor Addons and Templates plugin (versions before 1.7.1037) via tools like WPScan, Shodan, or by checking /wp-content/plugins/royal-elementor-addons/ for version indicators.
  2. Nonce Extraction: Visit the target site, navigate to a page where the Template Kit has been imported (or trigger the import), then open the browser developer console and type WprConfig to retrieve the nonce value from the exposed JavaScript configuration object.
  3. Craft Malicious Upload Request: Prepare a file to upload (e.g., evil.jpg or a file with a disguised extension) and construct a POST request targeting the AJAX endpoint:
curl -X POST http://example.com/wp-admin/admin-ajax.php \
  -F "action=wpr_addons_upload_file" \
  -F "triggering_event=click" \
  -F "wpr_addons_nonce=<NONCE>" \
  -F "uploaded_file=@evil.jpg"
  1. Access Uploaded File: The uploaded file is stored at /wp-content/uploads/wpr-addons/forms/ and is publicly accessible via the web server, enabling further exploitation such as serving malicious content or chaining with a file inclusion vulnerability (WPScan).

Indicators of compromise

  • Network: Unexpected POST requests to /wp-admin/admin-ajax.php with action=wpr_addons_upload_file from unauthenticated (non-logged-in) sources; multipart form-data uploads from unknown or suspicious IP addresses.
  • File System: Unexpected or suspicious files appearing in /wp-content/uploads/wpr-addons/forms/, particularly files with double extensions (e.g., .php.jpg), web shells, or files with unusual names not matching legitimate form submissions.
  • Logs: Web server access logs showing POST requests to admin-ajax.php with action=wpr_addons_upload_file from IPs with no prior site interaction; HTTP 200 responses to such requests from unauthenticated sessions.
  • Process: Unusual PHP process execution originating from files in the /wp-content/uploads/wpr-addons/forms/ directory (WPScan).

Mitigation and workarounds

Update the Royal Elementor Addons and Templates plugin to version 1.7.1037 or later, which includes proper authorization checks on the wpr_addons_upload_file action. As a temporary workaround, administrators can use a Web Application Firewall (WAF) rule to block POST requests to admin-ajax.php with action=wpr_addons_upload_file from unauthenticated users, or restrict access to the /wp-content/uploads/wpr-addons/forms/ directory via server configuration. Monitoring the uploads directory for unexpected file types is also recommended (WPScan).

Community reactions

The vulnerability was covered in Sucuri's December 2025 vulnerability patch roundup and noted in the Wordfence Intelligence weekly WordPress vulnerability report. The security community has flagged it on platforms including Bluesky and CIRCL's vulnerability lookup service. Overall community reaction is moderate given the medium CVSS score, though the unauthenticated nature of the exploit has drawn attention from WordPress security researchers (Sucuri Blog, Wordfence Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management